Skip to Content
📢 Breaking change: Applications using LedgerJS for transport implementation should migrate to the Device Management Kit (DMK). Learn more.

OpenPGP encryption

Looking to store secrets with your Ledger? Start with the Ledger Key Ring. It encrypts any file or text, needs the device only once at setup, and is recoverable from your seed. Use OpenPGP if you already work with GnuPG or need every decryption to require the device.

🛠️

For advanced users. This app is intended for developers already proficient with OpenPGP and GnuPG.

⚠️

Back up your keys. Keys are wiped by app updates, OS updates, and app reinstalls unless you back them up. Follow the backup and restore instructions in the app-openpgp repository  — losing your keys means losing access to anything encrypted against them.

Your Ledger can hold an OpenPGP private key that controls access to encrypted secrets—files, environment variables, API tokens, and other sensitive material your agents or tools consume. Because the private key never leaves the device, anything encrypted against your Ledger is unreadable without it physically present.

How it works

When you set up OpenPGP on your Ledger, a key pair is generated and stored on the device. You encrypt sensitive material against that public key. From that point, decryption requires the Ledger to be connected. Unplug the device and the secrets are opaque ciphertext to any process on the machine—including agents.

A stricter mode requires a manual tap on the device for each decryption event. In that mode, your Ledger becomes an active approval gate: even a process already running on your machine cannot read a secret without your explicit, on-device confirmation.

Which one should I use?

PointLedger Key RingOpenPGP
Device neededOnce for ring init; not for encrypt or decrypt.For every decryption.
Network neededYes, for encrypt and decrypt to restore the Ledger Sync trustchain.No network requirement for encryption or decryption.
Behavior after OS updateNo OS-update-specific behavior is documented. If setup must be restored, set up a new machine from the same Ledger seed; see Recovery.Keys are wiped by OS updates and must be restored from a backup.
RecoveryIf you lose the local password or replace the device, use a new machine with the same Ledger seed and run wallet-cli ring init; choose a new local password.Restore the OpenPGP key backup following the app-openpgp repository .
Known limitsRemoving a Ledger Sync member rotates the key, so existing ciphertext must be re-encrypted before removal.Intended for advanced OpenPGP/GnuPG users; private keys do not persist through app updates, OS updates, app reinstalls, or device replacement without a backup.
Best usepersonal secrets, tokens, env files, backups, from a terminal or an agent.Existing GnuPG workflows that need every decryption to require the device.

In the context of AI tools

This matters most in agent workflows where automation handles sensitive material. An agent that needs API keys or credentials to do its work can only access those secrets when your signer is present. In tap-required mode, it needs your confirmation for every individual access. For general-purpose agent secrets, files, tokens, and backups, use the Ledger Key Ring instead.

Further reading

Last updated on
Ledger
Copyright © Ledger SAS. All rights reserved. Ledger, Ledger Stax, Ledger Flex, Ledger Nano, Ledger Nano S, Ledger OS, Ledger Wallet, [LEDGER] (logo), [L] (logo) are trademarks owned by Ledger SAS.